Description
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Infographic Maker-iList Unspecified Vulnerability (2.7.0)
WordPress Plugin Mass Pages/Posts Creator Cross-Site Scripting (1.2.2)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5866)
WordPress Plugin Comment Rating Cross-Site Request Forgery (2.9.20)